cgminer_project CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

cgminer_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all cgminer_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk path handling, vendor risk buffer overflow, and vendor risk memory corruption, with potential vendor impact application crash across vendor surface software deployment use cases.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2018-10058 The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers. [email protected] 8.8 3.93% 2018-06-05 2026-06-17
CVE-2018-10057 The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write the miner configuration file to arbitrary locations on the server due to missing basedir restrictions (absolute directory traversal). [email protected] 6.5 2.36% 2018-06-05 2026-06-17
CVE-2014-4503 The parse_notify function in util.c in sgminer before 4.2.2 and cgminer 3.3.0 through 4.0.1 allows man-in-the-middle attackers to cause a denial of service (application exit) via a crafted (1) bbversion, (2) prev_hash, (3) nbit, or (4) ntime parameter in a mining.notify action stratum message. [email protected] 4.3 1.22% 2014-07-23 2026-06-17
CVE-2014-4501 Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unspecified impact via a long URL in a client.reconnect stratum message to the (1) extract_sockaddr or (2) parse_reconnect functions in util.c. [email protected] 10.0 2.91% 2014-07-23 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence